Legal & GRC Senior Manager – Tech Industry
Confidential · Riyadh, Saudi Arabia
قدّم وتابع مع أبلاي إيدجJob Title: Legal & GRC Senior Manager – Tech IndustryLocation: Riyadh, Saudi ArabiaCompany: ConfidentialRole Overview:We are seeking an accomplished Legal & GRC Senior Manager to lead and manage all legal, governance, risk, and compliance activities across the company's data center portfolio from development through operations. The Senior Manager shall ensure that all business units, partnerships, and capital projects are conducted within the framework of Saudi regulations, international standards, and the organization's governance charter - protecting legal integrity, supporting sustainable growth, and enabling compliant operations across development, sales, and capital investment cycles. This position plays a critical role in establishing corporate legal frameworks, leading regulatory compliance, directing corporate governance structures, implementing GRC systems, and mitigating legal risks across all business operations and data center facilities.Key Responsibilities:Legal Framework & Contract ManagementEstablish and oversee corporate legal frameworks covering EPC, O&M, MSAs, SLAs, colocation contracts, consultancy agreements, and all financial, technical, commercial, and insurance due diligence requirements.Lead contractual negotiations for hyperscaler, wholesale, and enterprise customer agreements ensuring balanced risk allocation.Draft, review, and negotiate commercial agreements across all business lines and project entities.Manage the full contract lifecycle including LOIs, lease agreements, renewals, amendments, terminations, and dispute resolution.Ensure balanced risk allocation in EPC and O&M contracts with zero material disputes.Establish and maintain standard contract templates, playbooks, and negotiation guidelines for consistent legal execution.Review and approve all major commercial transactions, partnership agreements, and vendor contracts.Regulatory Compliance & LicensingLead regulatory compliance with Communications, Space & Technology Commission (CST), Ministry of Communications and Information Technology (MCIT), National Cybersecurity Authority (NCA), and Securities and Exchange Commission (SEC) for data center licensing, power allocations, cybersecurity, and data-sovereignty frameworks.Ensure 100% compliance with legal and regulatory frameworks across all operations and business units.Manage regulatory licensing, permits, and approvals required for data center operations in Saudi Arabia.Monitor and advise on data sovereignty, cybersecurity regulations, and privacy laws including Saudi Personal Data Protection Law (PDPL).Stay updated on evolving technology regulations, digital economy legislation, and international compliance requirements.Coordinate with regulatory authorities for inspections, audits, and compliance matters.Develop and maintain regulatory compliance roadmaps and monitoring frameworks.Corporate Governance & Strategic AdvisoryDirect corporate governance structures including board charters, delegations of authority, policies, and RACI frameworks to ensure transparency and accountability across all subsidiaries and SPVs.Provide strategic advisory to senior leadership and the board on legal and governance matters including mergers, joint ventures, and capital structuring of project entities.Ensure shareholder reporting obligations are met including disclosure, policy adherence, and annual compliance statements.Develop, review, and implement corporate policies, codes of conduct, and compliance frameworks.Advise on corporate structuring, subsidiary governance, and SPV establishment and management.Support business development activities with legal analysis, feasibility assessments, and transaction structuring.Lead governance improvement initiatives and drive best practice adoption across the organization.GRC Systems & Compliance ManagementLead the design, implementation, and management of comprehensive GRC (Governance, Risk & Compliance) systems integrating incident reporting, risk registers, and compliance monitoring tools.Oversee compliance audits under ISO 27001, ISO 22301, ISO 9001, ISO 45001, and ESG frameworks, coordinating internal controls and external certifications.Develop and maintain GRC policies, procedures, and operational frameworks aligned with industry best practices.Ensure timely submission of corporate legal disclosures and company reporting compliance.Prepare and maintain documentation for internal and external regulatory audits and compliance assessments.Coordinate certification processes and maintain compliance records for audit readiness.Drive continuous improvement of GRC processes, systems, and reporting capabilities.Establish compliance monitoring dashboards and KPI tracking frameworks.Risk Management & Legal OperationsLead enterprise-wide legal risk management for claims, disputes, insurance coverage, and regulatory investigations.Develop and implement risk management frameworks, risk appetite statements, and risk mitigation strategies.Support business continuity and legal readiness for large-scale infrastructure projects and partnerships.Identify, assess, and mitigate legal risks across all business operations, technology projects, and capital investments.Manage relationships with external legal counsel, coordinate litigation strategies, and oversee legal budgets.Develop and maintain risk registers, heat maps, and legal risk mitigation strategies.Achieve risk mitigation effectiveness and reduction of legal exposure across all company data centers and operations.Conduct periodic risk reviews and present risk status updates to senior management and the board.Team Leadership & Capability BuildingLead, manage, and develop the legal and GRC team including compliance managers, governance officers, contract specialists, and legal analysts.Set clear performance objectives, conduct regular performance reviews, and provide coaching and professional development.Mentor multidisciplinary teams across legal, compliance, and governance functions to build institutional capability.Foster a culture of integrity, compliance, and professional excellence within the legal and GRC function.Develop training programs, awareness sessions, and legal toolkits to promote legal awareness and compliance culture across business units.Ensure adequate resources, capacity, and capability within the legal and GRC team to support business operations and growth.Stakeholder Coordination & RepresentationCollaborate with internal stakeholders including project delivery, project control, operations, sales and customer, and investment teams to provide legal and GRC support.Manage relationships with external stakeholders including regulatory bodies (CST, MCIT, NCA, SEC), EPC and O&M contractors, external legal, technical, commercial, and insurance providers.Liaise with telco and technology providers on legal and compliance matters.Coordinate with tenants including hyperscalers, government entities, enterprise clients, and their legal teams on contractual and compliance matters.Represent the legal and GRC function in executive meetings, board advisory sessions, strategic planning activities, and industry forums.Present legal and GRC performance reports, risk assessments, and strategic recommendations to senior management and the board.Qualifications:Bachelor's degree in Law or Engineering and Law (dual-qualified preferred).Fluency in English (written and spoken) is mandatory.Proficiency in Arabic is highly preferred.8 -12 years of professional experience in legal, compliance, and governance, with at least 5 years in leadership roles.Proven record managing legal and compliance functions in project and operations of data centers, telecom, and energy facilities.Experience structuring capital investments, SPVs, and joint ventures in the infrastructure sector.Strong understanding of data sovereignty, cybersecurity, and ESG regulatory frameworks in Saudi Arabia and globally.Demonstrated experience implementing and managing GRC systems, frameworks, and compliance monitoring tools.Master's degree (MBA, LL.M, or equivalent) is an advantage.Professional certifications such as CIPP, CIPM, GRCP, GRCA, or compliance-related qualifications are preferred.Membership with the Saudi Bar Association or equivalent legal professional body is preferred.Key Competencies:Strategic legal leadership and senior management capability.Deep GRC expertise and compliance management excellence.High ethical standards and integrity.Strong legal, governance, and compliance acumen.Strategic thinking and executive advisory expertise.Excellent negotiation, contract structuring, and deal-making skills.Enterprise risk management and mitigation capabilities.Culturally aware with strong leadership acumen.Ability to collaborate effectively across multi-disciplinary and international teams.Strong communication, presentation, and board-level stakeholder management skills.Analytical thinking, attention to detail, and data-driven decision-making.Team leadership and capability development excellence.Professionalism, accountability, and confidentiality.